Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 2 of 49
CVE-2016-2819P2HIGHCVSS 8.8PoCfixed in firefox 47.0-1 (sid)2016
CVE-2016-2819 [HIGH] CVE-2016-2819: firefox - Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x b...
Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.
Scope: local
sid: resolved (fixed in 47.0-1)
debian
CVE-2016-9899P2CRITICALCVSS 9.8PoCfixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9899 [CRITICAL] CVE-2016-9899: firefox - Use-after-free while manipulating DOM events and removing audio elements due to ...
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Scope: local
sid: resolved (fixed in 50.1.0-1)
debian
CVE-2018-5159P2CRITICALCVSS 9.8PoCfixed in firefox 60.0-1 (sid)2018
CVE-2018-5159 [CRITICAL] CVE-2018-5159: firefox - An integer overflow can occur in the Skia library due to 32-bit integer use in a...
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
Scope: local
debian
CVE-2016-1960P2HIGHCVSS 8.8PoCfixed in firefox 45.0-1 (sid)2016
CVE-2016-1960 [HIGH] CVE-2016-1960: firefox - Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in ...
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.
Scope: local
sid: resolved (fix
debian
CVE-2017-5447P2CRITICALCVSS 9.1PoCfixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5447 [CRITICAL] CVE-2017-5447: firefox - An out-of-bounds read during the processing of glyph widths during text layout. ...
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2017-5404P2CRITICALCVSS 9.8PoCfixed in firefox 52.0-1 (sid)2017
CVE-2017-5404 [CRITICAL] CVE-2017-5404: firefox - A use-after-free error can occur when manipulating ranges in selections with one...
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Scope: local
sid: resolved (fixed in 52.0-1)
debian
CVE-2017-5465P2CRITICALCVSS 9.1PoCfixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5465 [CRITICAL] CVE-2017-5465: firefox - An out-of-bounds read while processing SVG content in "ConvolvePixel". This resu...
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2019-9792P2CRITICALCVSS 9.8PoCfixed in firefox 66.0-1 (sid)2019
CVE-2019-9792 [CRITICAL] CVE-2019-9792: firefox - The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT ...
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Scope: local
sid: res
debian
CVE-2018-6126P2HIGHCVSS 8.8PoCfixed in firefox 60.0.2-1 (sid)2018
CVE-2018-6126 [HIGH] CVE-2018-6126: firefox - A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remot...
A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
Scope: local
sid: resolved (fixed in 60.0.2-1)
debian
CVE-2019-9813P3HIGHCVSS 8.8PoCfixed in firefox 66.0.1-1 (sid)2019
CVE-2019-9813 [HIGH] CVE-2019-9813: firefox - Incorrect handling of __proto__ mutations may lead to type confusion in IonMonke...
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
Scope: local
sid: resolved (fixed in 66.0.1-1)
debian
CVE-2023-6856P2HIGHCVSS 8.8fixed in firefox 121.0-1 (sid)2023
CVE-2023-6856 [HIGH] CVE-2023-6856: firefox - The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overfl...
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
Scope: local
sid: resolved (fixed in 121.0-1)
debian
CVE-2019-9816P3MEDIUMCVSS 5.9PoCfixed in firefox 67.0-2 (sid)2019
CVE-2019-9816 [MEDIUM] CVE-2019-9816: firefox - A possible vulnerability exists where type confusion can occur when manipulating...
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbird < 60.7, Fir
debian
CVE-2022-2200P3HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-2200 [HIGH] CVE-2022-2200: firefox - If an object prototype was corrupted by an attacker, they would have been able t...
If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code execution. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
Scope: local
sid: resolved (fixed in 102.0-1)
debian
CVE-2025-4918P3CRITICALCVSS 9.8fixed in firefox 138.0.4-1 (sid)2025
CVE-2025-4918 [CRITICAL] CVE-2025-4918: firefox - An attacker was able to perform an out-of-bounds read or write on a JavaScript `...
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.
Scope: local
sid: resolved (fixed in 138.0.4-1)
debian
CVE-2018-18505P3CRITICALCVSS 10.0fixed in firefox 65.0-1 (sid)2018
CVE-2018-18505 [CRITICAL] CVE-2018-18505: firefox - An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-...
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. Th
debian
CVE-2024-8381P3CRITICALCVSS 9.8fixed in firefox 130.0-1 (sid)2024
CVE-2024-8381 [CRITICAL] CVE-2024-8381: firefox - A potentially exploitable type confusion could be triggered when looking up a pr...
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
Scope: local
sid: resolved (fixed in 130.0-1)
debian
CVE-2021-38503P3CRITICALCVSS 10.0fixed in firefox 94.0-1 (sid)2021
CVE-2021-38503 [CRITICAL] CVE-2021-38503: firefox - The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowin...
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Scope: local
sid: resolved (fixed in 94.0-1)
debian
CVE-2026-4688P3CRITICALCVSS 10.0fixed in firefox 149.0-1 (sid)2026
CVE-2026-4688 [CRITICAL] CVE-2026-4688: firefox - Sandbox escape due to use-after-free in the Disability Access APIs component. Th...
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-2768P3CRITICALCVSS 10.0fixed in firefox 148.0-1 (sid)2026
CVE-2026-2768 [CRITICAL] CVE-2026-2768: firefox - Sandbox escape in the Storage: IndexedDB component. This vulnerability affects F...
Sandbox escape in the Storage: IndexedDB component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-4692P3CRITICALCVSS 10.0fixed in firefox 149.0-1 (sid)2026
CVE-2026-4692 [CRITICAL] CVE-2026-4692: firefox - Sandbox escape in the Responsive Design Mode component. This vulnerability affec...
Sandbox escape in the Responsive Design Mode component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian